Sub-groups resolution is rejected and Member Type is set to "Account" instead of "Group" for Account Collectors in RSA Identity Governance and Lifecycle
Originally Published: 2017-10-03
Article Number
Applies To
RSA Version/Condition: 6.9.1 P15- P19, 7.0.0 P04, 7.0.1
Issue
In the following example, we are using groups and sub-groups collected from Active Directory.
1. We have two groups in AD as below
2.Sub-Group is the member of Top-Group.
3. Account Collector with the below configuration for the groups.
4. Following is the subgroup resolution.
5. Collect data, then check the monitoring >> raw data >> Group Membership tab, you will find that the Top-Group to Sub-Group resolution is failing and the Sub-Group is collected as an "Account", not as a "group":
Cause
For version 7.0.0 and 7.0.1 this is fixed in 7.0.0 P05 and 7.0.1 P02 respectively.
Resolution
Related Articles
Generic REST Collector fails with GENERIC_REST_EXCEPTION_NULL_API_URL error when calling the Group Data operation in RSA I… 137Number of Views Application X is not a member of AppGroup 9Number of Views How to change a name of the change requests in RSA Identity Governance and Lifecycle 9Number of Views Termination rule sometimes fails to create change requests to disable accounts in specific applications in RSA Identity Go… 132Number of Views Generic REST Collector ignores the Response Timeout Setting configured in the Collector Definition in RSA Identity Governa… 70Number of Views
Trending Articles
RSA Authentication Manager 8.9 Setup and Configuration Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings. RSA Authentication Manager Upgrade Process
Don't see what you're looking for?